Travel Safely RSA TRAVEL SAFELY RSA

Privacy Policy

Last updated: 30 August 2026

Travel Safely RSA (“we”, “our”, “us”) operates the Travel Safely RSA mobile application and the Business Portal at www.travelsafelyrsa.co.za (“the website”). We are committed to protecting the personal information of all users and business registrants in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what data we collect, why we collect it, how it is used, and your rights regarding that data.

1. Information We Collect

From app users:

From business registrants (Business Portal):

2. How We Use Your Information

3. Lawful Basis for Processing (POPIA)

4. Data Sharing

We do not sell, rent, or trade your personal information to any third party. We use the following trusted sub-processors, each bound by their own privacy frameworks:

Business listing information (name, address, contact details, photos, hours, description) that you submit as a business registrant is displayed publicly within the app and is accessible to all app users. Place-suggestion content that is approved (place name, category and location) is likewise displayed publicly. Please only submit information you are comfortable being publicly visible.

5. Data Retention

6. Your Rights Under POPIA

As a data subject under the Protection of Personal Information Act 4 of 2013, you have the right to:

To exercise any of these rights, contact us at hello@travelsafelyrsa.co.za. We will respond within 30 days.

7. Security

We take reasonable and appropriate technical and organisational measures to protect your personal information, including Firebase security rules, role-based access controls, and encrypted HTTPS/TLS connections for all data in transit. Business login credentials are transmitted only via email to the address you registered with. No method of electronic storage or transmission is 100% secure; we encourage you to use a strong, unique password.

8. Children

Travel Safely RSA is not directed at persons under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us immediately and we will take steps to delete it.

9. Cross-Border Transfers

Your data may be processed on servers located outside South Africa, including in the United States (Google Firebase, Cloudinary, Google Maps Platform, Vercel). These transfers are subject to the privacy frameworks of the respective service providers, which provide comparable protection to POPIA.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. We will notify app users of material changes via an in-app notification. Business registrants will be notified by email. The revised policy will always be posted at this address with an updated date. Continued use of our services after the effective date constitutes acceptance.